Gentoo Archives: gentoo-server

From: Florian Huber <florian.huber@×××××××××××.de>
To: gentoo-server@g.o
Subject: Re: [gentoo-server] Intrusion Detection
Date: Mon, 15 Dec 2003 10:14:56
Message-Id: 1071504892.3419.7.camel@laptop.lindoze.home
In Reply to: [gentoo-server] Intrusion Detection by Karl Zander
1 Hello Karl,
2
3 On Mon, 2003-12-15 at 02:48, Karl Zander wrote:
4 > The Gentoo Security Guide seems to recommend AIDE (Advanced Intrusion
5 > Detection Environment) . And I would like to run that. But given that
6 > files in /bin, /sbin or /etc or other important places that AIDE may be
7 > monitoring can change when running emerge, how management intensive is it
8 > to run AIDE or any other intrusion detection?
9
10 A production server should not need that many updates, so the effort is
11 reasonable.
12 Check if sth. has changed, emerge, update aide database
13
14 > I think I read that AIDE was running on the Gentoo rsync server that was
15 > comprised so running it does seem like good practice.
16
17 IDS means intrusion DETECTION system, not PREVENTION! It cannot prevent
18 you system from being compromized (but a good configuration and regular
19 critical updates can...) - they only help you to understand what
20 happened, e.g. which files have been altered by a rootkit. Same for the
21 NIDS like snort and prelude...
22
23 HTH
24 Florian Huber
25
26 --
27 Florian Huber
28
29 Key ID: D9D50EA2
30 Fingerprint: 0241 C329 E355 9B94 8D34 F637 4EB9 1B1D D9D5 0EA2
31
32 BOFH Excuse #352:
33 The cables are not the same length.

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-server] Intrusion Detection Karl Zander <gentoolist@××××××××××××.com>